Bug 1479534 - Connection files with incorrect permission
Connection files with incorrect permission
Product: Fedora
Classification: Fedora
Component: NetworkManager (Show other bugs)
Unspecified Unspecified
unspecified Severity high
: ---
: ---
Assigned To: Lubomir Rintel
Fedora Extras Quality Assurance
Depends On:
  Show dependency treegraph
Reported: 2017-08-08 14:10 EDT by Bruno A. Crespo
Modified: 2017-08-08 15:21 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2017-08-08 15:21:05 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Bruno A. Crespo 2017-08-08 14:10:20 EDT
Description of problem:

When NetworkManager saves a plugin's connection file, it uses incorrect permissions and the file is rejected from this moment.

Version-Release number of selected component (if applicable):


How reproducible:


Steps to Reproduce:

[root@obelix ~]# cd /etc/NetworkManager/system-connections
[root@obelix system-connections]# nmcli conn add type vpn vpn-type openvpn con-name foo ifname '*'
Connection 'foo' (c6173ba8-878d-4667-8f34-af7b79515e7f) successfully added.
[root@obelix system-connections]# ls -l foo
-rw-r--r-- 1 root root 249 Aug  8 20:08 foo

Actual results:

The file has 0644 perms

Expected results:

The file must have 0600 perms

Additional info:

It happens with several plugins, not just openvpn
Comment 1 Bruno A. Crespo 2017-08-08 15:21:05 EDT
It seems that my directory /etc/NetworkManager and several subdirectories has a default ACL.  I don't understand why, because I don't put this ACL.

Note You need to log in before you can comment on or make changes to this bug.